LIVE NEWS
  • European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
  • Coolest Places Along Route 66: Cities, Towns, Restaurants
  • Budget would cut Pentagon research by one-third. Can industry compensate?
  • Young Americans Are Turning Bankruptcy. Tell Us Your Story.
  • Trump seeks to double number of ship requests with 2027 defense budget
  • I’ve witnessed nearly 100 rocket launches. Artemis II was like nothing I’ve ever experienced.
  • What we know so far
  • Permissioned “DeFi”: The Quiet Shift Reshaping Open Finance
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Cybersecurity

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

primereportsBy primereportsApril 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
Share
Facebook Twitter LinkedIn Pinterest Email


The European Commission (EC) has confirmed that hackers stole over 300GB of data from its AWS environment using an API key compromised in the Trivy supply chain attack.

The incident occurred on March 24 and was initially disclosed on March 27, when the EC warned that cloud infrastructure hosting its resources for the Europa.eu platform had been breached.

Now, CERT-EU reveals that the hack involved an AWS cloud account that is part of the backend for the Europa.eu hosting service, which supports public websites for the EC and other European Union entities.

Hackers gained access to the AWS account using an API key compromised on March 19 in the supply chain attack on Aqua Security’s Trivy vulnerability scanner, carried out by the TeamPCP hacking group.

“The European Commission was unwittingly using a compromised version of Trivy during the relevant timeframe, having received it through normal software update channels,” CERT-EU explains.

Using the compromised AWS key, the attackers created and attached a new access key to a user account and carried out reconnaissance, according to the EU’s cybersecurity team.

Advertisement. Scroll to continue reading.

“This key granted control over other AWS accounts affiliated with the European Commission. On the same day, the threat actor attempted to discover additional secrets by launching TruffleHog, a tool commonly used for scanning secrets and validating AWS credentials by calling the Security Token Service (STS),” CERT-EU says.

Wiz recently explained that TeamPCP wasted no time validating stolen credentials, launching discovery operations, exfiltrating more data, and attempting lateral movement.

“The threat actor used the compromised AWS secret to exfiltrate data from the affected cloud environment. The exfiltrated data relates to websites hosted for up to 71 clients of the Europa web hosting service: 42 internal clients of the European Commission, and at least 29 other Union entities,” CERT-EU notes.

On March 28, the infamous ShinyHunters extortion group added the stolen information to its Tor-based leak site.

European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

The 340GB of uncompressed data includes personal information such as names, email addresses, and usernames, mainly from the EC’s websites. Users across multiple EU entities were likely affected as well, CERT-EU says.

Roughly 2.22GB of the data, or 51,992 files, represents automated notifications, including bounce-back messages containing original user-submitted content, which could include personal information.

“The analysis of the databases linked to the hosted websites is underway. Given the volume and intricate nature of the data involved, this process requires a considerable amount of time,” CERT-EU notes.

Upon learning of the compromise, the EC revoked the compromised account’s rights, deactivated and rotated the compromised credentials, and notified the relevant data protection bodies. The Commission also confirmed that the incident did not affect its internal systems.

Related: React2Shell Exploited in Large-Scale Credential Harvesting Campaign

Related: T-Mobile Sets the Record Straight on Latest Data Breach Filing

Related: 250,000 Affected by Data Breach at Nacogdoches Memorial Hospital

Related: Mercor Hit by LiteLLM Supply Chain Attack

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleCoolest Places Along Route 66: Cities, Towns, Restaurants
primereports
  • Website

Related Posts

Cybersecurity

Cisco IMC auth bypass vulnerability allows attackers to alter user passwords (CVE-2026-20093)

April 3, 2026
Cybersecurity

Trump budget proposal would cut hundreds of millions more from CISA

April 3, 2026
Cybersecurity

New ‘Storm’ Infostealer Remotely Decrypts Stolen Credentials

April 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20258 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
  • Coolest Places Along Route 66: Cities, Towns, Restaurants
  • Budget would cut Pentagon research by one-third. Can industry compensate?
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.